VDB
Sign up
HIGH7.5

GHSA-8959-rfxh-r4j4

XWiki vulnerable to Denial of Service attack through attachments

Quick fix

GHSA-8959-rfxh-r4j4 — org.xwiki.platform:xwiki-platform-distribution-war: upgrade to the fixed version with the command below.

# pom.xml: bump <version>14.10.18</version> for org.xwiki.platform:xwiki-platform-distribution-war

Details

### Impact

A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, could cause a denial of service issue via CPU consumption.

### Patches This vulnerability has been patched in XWiki 14.10.18, 15.5.3 and 15.8 RC1.

### Workarounds

The workaround is to download [commons-compress 1.24](https://search.maven.org/remotecontent?filepath=org/apache/commons/commons-compress/1.24.0/commons-compress-1.24.0.jar) and replace the one located in XWiki `WEB-INF/lib/` folder.

### References

https://jira.xwiki.org/browse/XCOMMONS-2796

### For more information

If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki.org](https://jira.xwiki.org/) * Email us at [Security Mailing List](mailto:security@xwiki.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.xwiki.platform:xwiki-platform-distribution-war
Introduced in: 14.10Fixed in: 14.10.18
Fix# pom.xml: bump <version>14.10.18</version> for org.xwiki.platform:xwiki-platform-distribution-war
Maven/org.xwiki.platform:xwiki-platform-distribution-war
Introduced in: 15.0-rc-1Fixed in: 15.5.3
Fix# pom.xml: bump <version>15.5.3</version> for org.xwiki.platform:xwiki-platform-distribution-war
Maven/org.xwiki.platform:xwiki-platform-distribution-war
Introduced in: 15.6-rc-1Fixed in: 15.8-rc-1
Fix# pom.xml: bump <version>15.8-rc-1</version> for org.xwiki.platform:xwiki-platform-distribution-war

References